Home / CNN News / Data leaked on 6 million Verizon users

Data leaked on 6 million Verizon users

How to protect yourself from hackers

Verizon confirmed on Wednesday the personal data of 6 million customers has leaked online.

The security issue, uncovered by research from cybersecurity firm UpGuard, was caused by a misconfigured security setting on a cloud server due to “human error.”

The error made customer phone numbers, names, and some PIN codes publicly available online. PIN codes are used to confirm the identity of people who call for customer service.

No loss or theft of customer information occurred, Verizon told CNN Tech.

UpGuard — the same company that discovered leaked voter data in June — initially said the error could impact up to 14 million accounts.

Chris Vickery, a researcher at UpGuard, discovered the Verizon data was exposed by NICE Systems, an Israel-based company Verizon was working with to facilitate customer service calls. The data was collected over the last six months.

Vickery alerted Verizon to the leak on June 13. The security hole was closed on June 22.

The incident stemmed from NICE security measures that were not set up properly. The company made a security setting public, instead of private, on an Amazon S3 storage server — a common technology used by businesses to keep data in the cloud. This means Verizon data stored in the cloud was temporarily visible to anyone who had the public link.

ZDNet first reported the breach.

Related: Data of almost 200 million voters leaked online by GOP analytics firm

The security firm analyzed a sample of the data and found some PIN codes were hidden but others were visible next to phone numbers.

UpGuard declined to disclose how the leaked data was discovered.

Dan O’Sullivan, a Cyber Resilience Analyst with UpGuard, said exposed PIN codes is a concern because it allows scammers to access someone’s phone service if they convince a customer service agent they’re the account holder.

“A scammer could receive a two-factor authentication message and potentially change it or alter [the authentication] to his liking,” O’Sullivan said. “Or they could cut off access to the real account holder.”

Verizon customers should update their PIN codes and not use the same one twice, O’Sullivan advises.

The is the latest leak to surface from a misconfigured Amazon S3 storage unit. In June, an analytics firm exposed the data of almost 200 million voters, and earlier this month, an insecure server leaked 3 million WWE fans’ data last week.

Why does this keep happening? Amazon secures these servers by default. This means the errors that occur are due to changes someone makes with a security setting — typically by accident, O’Sullivan said.

O’Sullivan says the Verizon case highlights how many third-parties have access to our personal data.

“Cyber risk is a fact of life for any digital service,” O’Sullivan said. “As data becomes more powerful and more accessible, the potential consequences for it to be misused also becomes more dangerous.”

CNNMoney (New York) First published July 12, 2017: 4:14 PM ET

Check Also

BankyW & Adesua Etomi step out in style for the Arabian themed premiere of ‘The Wedding Party 2’ (photos)

Share on Facebook Tweet on Twitter Co-stars and real life celebrity couple, BankyW and Adesua …

VP Osinbajo takes selfie with market women and children at Ikenne

[unable to retrieve full-text content]https://wowplus.net/vp-osinbajo-takes-selfie-market-women-children-ikenne/

Agbani Darego finally shows us her tall and gaddamit Hot husband…(photo)

Share on Facebook Tweet on Twitter Since their wedding in April 2017, this is the …

‘I won’t lie, I have prayed for an enemy to die before’ – Daddy Freeze writes

Share on Facebook Tweet on Twitter According to controversial OAP, Daddy Freeze ‘I won’t lie, …

The Future Awards 2017: Full list of winners

The 12th edition of The Future Awards 2017 held last night at the Federal Palace …